CISA Advisory: Nx Console & GitHub Supply Chain Compromises
CISA has issued an advisory on two active software supply chain intrusion campaigns: a compromise of GitHub via a malicious Nx Console VS Code extension (CVE-2026-48027), and the 'Megalodon' campaign injecting malicious GitHub Action workflows to harvest CI/CD secrets and cloud credentials. The incidents affect enterprise, cloud, and DevOps environments globally, with potential for broad credential theft across AWS, GCP, Azure, and other platforms. While technically significant, no named insured entities, quantified losses, or confirmed claims have been identified, limiting immediate London Market materiality.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway: Widespread credential harvesting across enterprise CI/CD pipelines creates plausible downstream cyber insurance loss pathway via ransomware deployment, data exfiltration, or business interruption using harvested cloud credentials. Evidence: CISA KEV listing, confirmed exfiltration of GitHub internal repositories, and broad scope of affected credential types (AWS, GCP, Azure, SSH, Docker tokens) indicate material exposure across cyber insurance books. Limit: No named insured commercial entities confirmed as victims, no quantified loss estimates, and no confirmed downstream attacks reported β impact remains potential rather than realized, warranting monitoring rather than immediate claims action.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts